Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can someone explain me why whenever SQL is mentioned then always somebody talks about SQLi?

like query parametrisation is supported by everything, database user can be read only

additionally if you want to go hard, then you can always compare ASTs generated query from user with query that's exposed by that endpoint

Why SQL Injection is still a thing?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: